spf-discuss
[Top] [All Lists]

Re: on CAs as reputation providers; an argument for metric-based reputation services

2003-12-08 14:41:29
When I get my mail working I will email the position paper.

I define three accreditation dimensions

Identity
Policy.
audit

All three together are mos effective but all provide some value



 -----Original Message-----
From:   Meng Weng Wong
Sent:   Mon Dec 08 11:08:57 2003
To:     spf-discuss(_at_)v2(_dot_)listbox(_dot_)com
Subject:        Re: [spf-discuss] on CAs as reputation providers; an
argument for metric-based reputation services

On Mon, Dec 08, 2003 at 01:36:09PM -0500, Meng Weng Wong wrote:
| 
| On Mon, Dec 08, 2003 at 05:21:46AM -0800, Hallam-Baker, Phillip wrote:
| | 
| | 
| | The cost of a ca issued  cert is policy enforcement. 
| | 
| 
| To expand on the idea of policy enforcement:
| 
| Judging the people who pay you money is not a tidy business model.  It
| may be better for a business to focus on providing reputation services
| rather than coupling reputation to certificates.
| 

Sorry for the long rants; I am a plodder.

I guess what I'm really saying is that if VeriSign wants to sell
people certs for domainkeys, they should; but they should not revoke
those certs even if they turn out to be spammers.  A reputation system
is still needed.

-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.9.txt
To unsubscribe, change your address, or temporarily deactivate your
subscription, 
please go to
http://v2.listbox.com/member/?listname(_at_)©#«Mo\¯HÝÜîU;±¤Ö¤Íµø?¡

-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.9.txt
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname(_at_)©#«Mo\¯HÝÜîU;±¤Ö¤Íµø?¡